steps: - name: seed-push-build image: alpine:3.20 commands: - echo "No-op push build." - echo "Exists only so woodpeckerci/plugin-trigger's last-successful" - echo "lookup (which only matches push-event builds) has a build to find." when: event: push - name: show-deployment-request image: alpine:3.20 environment: ZOT_USERNAME: from_secret: zot_username ZOT_PASSWORD: from_secret: zot_password SOPS_AGE_KEY: from_secret: sops_age_key DEPLOY_SSH_KEY: from_secret: deploy_ssh_key commands: - 'echo " ARTIFACT=$ARTIFACT"' - 'echo " TARGET=$TARGET"' - test -n "$ARTIFACT" || (echo "ERROR - ARTIFACT param missing" && exit 1) - test -n "$TARGET" || (echo "ERROR - TARGET param missing" && exit 1) - test -f "hosts/$TARGET" || (echo "ERROR - unknown host alias $TARGET" && exit 1) - . "hosts/$TARGET" - 'echo "Resolved host alias $TARGET -> $SSH_USER@$SSH_HOST"' # Tooling: oras (artifact retrieval) and sops (secret decryption). - apk add --no-cache curl openssh-client - curl -sL "https://github.com/oras-project/oras/releases/download/v1.3.4/oras_1.3.4_linux_amd64.tar.gz" -o /tmp/oras.tar.gz - mkdir -p /tmp/oras-install && tar -xzf /tmp/oras.tar.gz -C /tmp/oras-install - install /tmp/oras-install/oras /usr/local/bin/oras - curl -sL "https://github.com/getsops/sops/releases/download/v3.13.3/sops-v3.13.3.linux.amd64" -o /usr/local/bin/sops - chmod +x /usr/local/bin/sops # Retrieve the exact deployment artifact by digest/tag reference. - mkdir -p /tmp/deploy-bundle && cd /tmp/deploy-bundle - oras login "registry.ci.poc.mehl.mx" -u "$ZOT_USERNAME" -p "$ZOT_PASSWORD" - oras pull "$ARTIFACT" - test -f compose.yaml || (echo "ERROR - compose.yaml missing from artifact" && exit 1) - test -f secrets.prod.env || (echo "ERROR - secrets.prod.env missing from artifact" && exit 1) - test -f release.env || (echo "ERROR - release.env missing from artifact" && exit 1) # Decrypt the service's secrets transiently, using the deployment age key. - sops --decrypt secrets.prod.env > /tmp/deploy-bundle/secrets.decrypted.env - chmod 600 /tmp/deploy-bundle/secrets.decrypted.env # Set up the SSH key used to reach the target host. - mkdir -p -m 700 /tmp/ssh - echo "$DEPLOY_SSH_KEY" > /tmp/ssh/id_deploy - chmod 600 /tmp/ssh/id_deploy # Ensure the remote working directory exists, then transfer # compose.yaml, release.env, the decrypted secrets and the generic # bin/deploy-compose script to the target host, run the deployment, # and remove the plaintext secrets. Kept as a single commands: item # (one shell script) rather than several, since separate ssh/scp # list items have intermittently triggered a Woodpecker command # parsing bug (log-streaming artifact, not a real shell syntax # error - confirmed by direct SSH inspection of target1's state # after affected runs). - | set -e ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \ $SSH_USER@$SSH_HOST mkdir -p /tmp/poc-deploy scp -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \ compose.yaml release.env secrets.decrypted.env \ $SSH_USER@$SSH_HOST:/tmp/poc-deploy/ scp -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \ $CI_WORKSPACE/bin/deploy-compose \ $SSH_USER@$SSH_HOST:/tmp/poc-deploy/ ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \ $SSH_USER@$SSH_HOST chmod +x /tmp/poc-deploy/deploy-compose ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \ $SSH_USER@$SSH_HOST /tmp/poc-deploy/deploy-compose registry.ci.poc.mehl.mx $ZOT_USERNAME $ZOT_PASSWORD ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \ $SSH_USER@$SSH_HOST rm -f /tmp/poc-deploy/secrets.decrypted.env - echo "Deployment finished." when: event: [deployment, manual] when: event: [deployment, manual, push]